Harden form auth and submission handling

This commit is contained in:
2026-07-09 23:53:40 +07:00 Unverified
parent 2c82d55839
commit 8c0cc4492b
43 changed files with 747 additions and 534 deletions
+13 -13
View File
@@ -1,18 +1,13 @@
import { NextResponse } from "next/server";
import { getServerSession } from "next-auth";
import { authOptions } from "@/app/api/auth/[...nextauth]/route";
import { requireAdmin } from "@/lib/auth";
const MAX_UPLOAD_BYTES = 1024 * 1024;
export async function POST(req: Request) {
try {
const session = await getServerSession(authOptions);
const adminIds = (process.env.ADMIN_DISCORD_IDS ?? "")
.split(",")
.map((s) => s.trim())
.filter(Boolean);
const discordId = (session?.user as { discordId?: string } | undefined)
?.discordId;
if (!discordId || !adminIds.includes(discordId)) {
try {
await requireAdmin();
} catch {
return NextResponse.json({ error: "Unauthorized" }, { status: 401 });
}
@@ -27,6 +22,10 @@ export async function POST(req: Request) {
return NextResponse.json({ error: "Only image files are allowed" }, { status: 400 });
}
if (file.size > MAX_UPLOAD_BYTES) {
return NextResponse.json({ error: "Image must be 1MB or smaller" }, { status: 400 });
}
const allowedExtensions = ["png", "jpg", "jpeg", "webp", "gif"];
const originalExt = (file.name.split(".").pop() || "").toLowerCase();
@@ -40,8 +39,9 @@ export async function POST(req: Request) {
const dataUri = `data:${mimeType};base64,${base64}`;
return NextResponse.json({ url: dataUri });
} catch (error: any) {
} catch (error) {
console.error("Upload error:", error);
return NextResponse.json({ error: error.message || "Internal server error" }, { status: 500 });
const message = error instanceof Error ? error.message : "Internal server error";
return NextResponse.json({ error: message }, { status: 500 });
}
}